NoaBot: 2023 Mirai-Based Virus Targets SSH Servers for Crypto Mining

A new Mirai-based botnet called NoaBot is being used by threat actors as part of a crypto mining campaign since the beginning of 2023.

This is based on the fact that threat actors have also experimented with dropping P2PInfect in place of NoaBot in recent attacks targeting SSH servers, indicating likely attempts to pivot to custom malware.

"NoaBot is compiled with uClibc, which seems to change how antivirus engines detect the malware," Kupchik noted.

"While other Mirai variants are usually detected with a Mirai signature, NoaBot's antivirus signatures are of an SSH scanner or a generic trojan."

"The malware's method of lateral movement is via plain old SSH credentials dictionary attacks," Kupchik said.

0 Comments

End of content

No more pages to load